Impact
File Browser versions before 2.63.22 do not validate access rules for descendant items during recursive copy, rename, or delete operations. This flaw allows an authenticated user to manipulate any file under an allowed parent directory, thereby bypassing path‑based access controls. The result is confidentiality and integrity violations of files that should have been protected.
Affected Systems
The vulnerability is present in File Browser deployment by the filebrowser vendor. All instances using versions earlier than 2.63.22 are affected, regardless of how the application is hosted or configured.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity. EPSS is not available, and the vulnerability is not currently listed in CISA KEV. Attackers need only authenticated credentials and are able to exploit the flaw by issuing standard recursive commands on a permitted parent directory; no additional privilege or network access beyond the application login is required.
OpenCVE Enrichment